Grotabyte
Contact SalesBook a Demo

Who it’s for / Records & Information Governance

Grotabyte for Records and Information Governance

You have a retention schedule. The question is whether anything in the organisation actually obeys it. A schedule that exists as a spreadsheet, while records quietly accumulate forever because deleting them felt risky, is worse than no schedule at all — it is a documented standard you are visibly not meeting.

Rated 5 out of 5. “Ten-year holds, answered by self-service.” — College of DuPage

Also for: Data Protection Officer

What you are accountable for

You are accountable for a retention schedule that is genuinely in force: records kept exactly as long as the rule requires, destroyed when it expires, and provably so in both directions.

What makes that hard

A schedule on paper is not a schedule in force

Policy documents do not delete anything. If disposal depends on someone remembering to run it, the real retention period is 'forever', and every extra year is discoverable, storable and breachable.

Two rules, one record

A message can be a financial record, a personnel record and evidence in a matter at the same time, with three different periods attached. Without a stated conflict rule, disposal decisions become individual judgement calls that nobody wants to sign.

Certifying a destruction you did not watch

A certificate generated from the schedule describes what was supposed to happen. If it does not describe what was actually destroyed, it is a document that will be read back to you.

Erasure requests that collide with holds

An individual demands erasure; the record is under legal hold. Both obligations are real, they point in opposite directions, and whichever way you go you need the reasoning written down at the moment you decided.

What Grotabyte gives you

Templates that carry their citation, disabled until you say so

Ten retention templates, six citing the statute behind them — SEC 17a-4(a) and (b), FINRA 4511(c), SOX §802, HIPAA and MiFID II. All ten ship disabled by design, so the schedule in force is the one you approved rather than a vendor default you inherited.

Conflicts resolved by a stated rule

Where more than one rule applies to a record, the longest applicable rule wins, and the clock runs from the moment the record entered custody rather than from an editable date field. Legal holds override retention entirely until released, and release requires a second approver.

Destruction certified against what was destroyed

Certified destruction runs in four layers, and the certificate is produced by querying the index at the moment it is issued. It describes the records that were actually destroyed, not the ones the schedule expected to destroy.

Erasure with dual control, refusals with a basis

GDPR Article 17 erasure requires two approvers, so no single administrator erases unilaterally. Where a record is under legal hold the erasure is refused and the refusal is written to the ledger with the legal basis for it — which is the artefact a supervisory authority will ask to see.

Knowing what you are holding

Eighteen DLP detectors across twelve countries and regions, with every national identifier checksum-verified, so a number that fails its checksum is never raised as a match — no false positives across a real-world reference corpus. Matched evidence is masked by construction, so an alert about sensitive data does not itself disclose it.

One checkable thing

Certified destruction runs in four layers, and the certificate queries the index at the moment of issue — so it attests to what was destroyed rather than to what was scheduled.

Questions this role asks

What happens when two retention rules apply to the same record?

The longest applicable rule wins, and it is applied automatically rather than left as a judgement call for whoever is running disposal that quarter. The clock runs from the point the record entered custody, so the period is anchored to something the archive observed rather than to a date field somebody could edit. A legal hold outranks all of it — held material is not disposed of at all until the hold is released, and release takes a second approver.

Someone has asked us to erase their data, but the record is under legal hold.

The erasure is refused, and the refusal is recorded on the tamper-evident ledger together with the legal basis for it. That gives you a contemporaneous, dated artefact showing that the request was considered and why the competing obligation prevailed — which is a far better position than an unrecorded decision or an erasure that destroys evidence. When the hold is released, the request can be actioned, and Article 17 erasure itself requires two approvers.

Can we adopt your retention templates without adopting your defaults?

That is the intended path — every template ships disabled. You review each one, including the six that carry the statutory citation they implement, adjust the periods to your own schedule, and enable them deliberately. Nothing starts deleting because a template exists, and no rule takes effect on a vendor's timetable.

Records management →Retention & destruction →Defensible deletion whitepaper →GDPR compliance →
Book a demo Join a Wednesday session

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.